RE: nft bewilderment

2020-05-05 Thread ghe
Close the ticket. wiki.archlinux.org on nftables looks like it answers
enough of my questions to keep me going for a few days...

Thanks for the replies and suggestions.

-- 
Glenn English



Re: nft bewilderment

2020-05-05 Thread rhkramer
On Tuesday, May 05, 2020 03:01:02 PM ghe wrote:
> > Aside from advice like google (ddg) them, why don't you list them here.

Sorry, I wasn't very clear -- I was trying to suggest that you google (or ddg) 
and list here the terms that you don't understand.




> 
> There were so many I don't remember all of them.
> 
> A few:
> 
> The Debian pages on nft.
> The Arch pages.
> The Ubuntu pages.
> The man page.
> The nft site.
> Serverfault.
> Admin magazine.
> 
> Amazon looking for O'Reilly etc. books.
> 
> Sorry. That's almost certainly not all. It's from the sites I printed
> and sites I saved bookmarks to.
> 
> And I use DDG, not Google. I'll try Google...



Re: nft bewilderment

2020-05-05 Thread ghe


‐‐‐ Original Message ‐‐‐
On Tuesday, May 5, 2020 12:42 PM,  wrote:

> On Tuesday, May 05, 2020 01:50:00 PM ghe wrote:
>
> > This wiki explains a lot, but seems to assume I know a lot to begin
> > with. Which I don't.
> > I know iptables quite well, but nft has added a lot of terms and
> > features to the mix. That's fine, but I haven't been able to find out
> > much about some of them.
>
> Aside from advice like google (ddg) them, why don't you list them here.

There were so many I don't remember all of them.

A few:

The Debian pages on nft.
The Arch pages.
The Ubuntu pages.
The man page.
The nft site.
Serverfault.
Admin magazine.

Amazon looking for O'Reilly etc. books.

Sorry. That's almost certainly not all. It's from the sites I printed
and sites I saved bookmarks to.

And I use DDG, not Google. I'll try Google...

-- 
Glenn English



Re: nft bewilderment

2020-05-05 Thread rhkramer
On Tuesday, May 05, 2020 01:50:00 PM ghe wrote:
> This wiki explains a lot, but seems to assume I know a lot to begin
> with. Which I don't.
> 
> I know iptables quite well, but nft has added a lot of terms and
> features to the mix. That's fine, but I haven't been able to find out
> much about some of them.

Aside from advice like google (ddg) them, why don't you list them here.



Re: nft bewilderment

2020-05-05 Thread ghe



> It's not clear from your message if you've seen this.

> https://wiki.nftables.org

Yes, I have. Lots of help, but lots of info missing.

This wiki explains a lot, but seems to assume I know a lot to begin
with. Which I don't.

I know iptables quite well, but nft has added a lot of terms and
features to the mix. That's fine, but I haven't been able to find out
much about some of them.

> Kind regards,
> Andrei

-- 
Glenn English



Re: nft bewilderment

2020-05-05 Thread Andrei POPESCU
On Ma, 05 mai 20, 10:57:24, ghe wrote:
> Buster, Supermicro desktop, nft noob
> 
> Can anyone recommend a book or website with a thorough explanation of
> nft (the iptables replacement)?

It's not clear from your message if you've seen this.

https://wiki.nftables.org

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser


signature.asc
Description: PGP signature


nft bewilderment

2020-05-05 Thread ghe
Buster, Supermicro desktop, nft noob

Can anyone recommend a book or website with a thorough explanation of
nft (the iptables replacement)?

I'm working on rewriting my aged packet filter shell script (big and
from the ipchains days) with nft and python. I've spent several hours on
the web, and I've found lots of info about nft, but nowhere have I come
across a plain and straightforward explanation -- lots of 'how nft is a
huge improvement over iptables', but very little about why or what
things mean or what's necessary to make things happen.

So far, the best I've been able to do is just change the commands in
examples and test them to see what happens.

Like, for one example: What's a 'base chain', what's not, why do both
exist, what's the functional difference, what do the various components
of the command line mean, etc.

-- 
Glenn English